Industry guide · Supply Chain

Product Stewardship and Substance Compliance Software: How Do You Roll Up 900 Supplier Declarations Before Friday?

Product Stewardship Substance Compliance software visual showing test tubes, combine, and percent.
The short answer

Plan on $60,000 to $140,000 for a first release in 12 to 16 weeks covering supplier declaration intake, part level substance data, and automated rollup from bill of materials to finished product statement. A full stewardship platform adding supplier campaign management, SCIP submissions, conflict minerals reporting, customer portal responses and change monitoring runs $180,000 to $400,000 phased over 6 to 12 months, in our delivery experience. Build when you carry more than roughly 5,000 purchased part numbers across multiple product lines and your rollup is a spreadsheet exercise. Do not build if you have a few hundred parts and one regulated market: Assent or iPoint will cost less than the maintenance of your own system.

Why substance compliance quietly becomes a market access problem

A Tuesday email from a customer's procurement portal asks for a full material disclosure for assembly 4471-B, plus a REACH statement, plus confirmation on two substances added to the candidate list, by Friday. The compliance manager opens the shared drive. There are around 900 supplier declarations in it. Perhaps 300 are more than three years old. Sixty are scans of scans. A dozen are Excel templates the supplier filled in by writing not applicable across every row. The bill of materials for 4471-B has changed twice this year because purchasing qualified an alternate connector, and the alternate has no declaration at all.

By Thursday afternoon the answer that goes back is a statement of belief, signed by someone whose job depends on it being true, based on data nobody can fully evidence. Everyone in this industry knows that email. It is not a paperwork problem. If the statement is wrong, the consequence is not a fine in the first instance, it is a customer removing your part from their approved list, which means a product line loses a market.

The stack is typically an ERP (Enterprise Resource Planning) holding purchasing and bills of material, a PLM holding engineering structures, a shared drive of declarations, an Excel rollup workbook maintained by one person, and possibly a subscription to Assent, Sphera or iPoint for supplier campaigns. Each holds a piece. None of them holds the join between a bill of material revision, the specific supplier part that was actually bought against each line, the declaration covering that part on that date, and the finished product statement you issued to a customer last quarter. That join is the whole job, and it lives in a workbook.

Problem 1: declarations arrive as documents and your rollup needs data

There is a perfectly good standard for this. IPC-1752A defines a machine readable declaration format, and IEC 62474 defines a substance data exchange. A minority of your suppliers will use them. The rest send a PDF on letterhead, or your own Excel template completed wrongly, or a certificate of conformance that says the part complies with RoHS and nothing else.

The subscription platforms are genuinely good at the campaign side of this. They chase suppliers, they escalate, they have relationships. What they are less good at is your parts. Their data model is theirs, your part numbering and approved vendor list logic is yours, and matching a supplier document referencing their part number to your internal part number across revisions, alternates and manufacturer part numbers is where the accuracy is lost. That matching is exactly the work that gets done by hand at 6pm.

What a custom build does: treat the document as evidence and the extracted data as a record with a provenance link back to the page it came from. Document extraction is one of the two places AI earns its keep here, reading the substance table, the declaration scope, the signatory and the date out of a hundred different layouts and putting them into your schema for human confirmation. The second place is matching, resolving a supplier's part string against your approved vendor list including manufacturer part numbers and known abbreviations. In our builds these two together take the manual handling of a declaration from ten or fifteen minutes to under two, and more importantly they make every extracted value traceable to a source page during an audit.

Problem 2: rollup logic is specific to how your company models a product

Rolling substance data from parts to a finished product sounds like arithmetic. It is not, because product structures are opinionated. Phantom assemblies exist in the bill of material but not in the physical product. Alternates mean the part in the box depends on which one purchasing had in stock that week. Process chemicals such as plating, flux, adhesive and marking ink are physically present and frequently absent from the bill of material entirely. Configurable products have a structure that only resolves at order time.

Then there is the threshold logic. RoHS restrictions apply at homogeneous material level, not at part level, so a declaration that gives you a percentage against the whole component is not directly usable. REACH candidate list obligations for articles use a 0.1 percent by weight threshold, and how that threshold applies through an assembly is a question your regulatory counsel should answer for your products, not a setting in a vendor default.

What a custom build does: encode your structure rules explicitly. Phantom handling, alternate resolution, process chemical attachment at operation level, and a documented rule for how thresholds propagate for each regime you report against. The output is not a single compliant flag, it is a statement with a computed basis: which parts contributed, which are covered by declarations, which are assumed, and what the exposure is if an assumption is wrong. That last column is what turns compliance from a claim into a risk position management can act on.

Problem 3: the lists move and your parts do not

The REACH candidate list of substances of very high concern is updated periodically, typically twice a year, and each update can turn a part you have been buying for a decade into a reportable article overnight. RoHS exemptions expire on published schedules. PFAS restrictions are moving in multiple jurisdictions at once. None of that involves any change on your side, which is precisely why it gets missed.

The commercial platforms do monitor the lists and that is a fair reason to buy one. What they cannot do is tell you which of your open customer commitments are affected, because they do not hold the record of what you told which customer on what basis and when.

What a custom build does: keep every statement you have issued as a versioned object with the data it was computed from. When a list updates, the system re evaluates every affected product and produces two work queues: parts needing a fresh declaration, and customers who received a statement that is now stale. That second queue is the one that protects the relationship, because telling a customer before their auditor does is a completely different conversation from telling them after.

Problem 4: SCIP, conflict minerals and every customer's own portal

The EU SCIP database requires notification of articles containing candidate list substances above the threshold placed on the EU market. Conflict minerals reporting under the United States rules runs on the CMRT template. Some customers want IPC-1752A back. Others want their own spreadsheet, with their own column names, uploaded to their own portal, quarterly.

This is the part that consumes a compliance team's week and creates no value beyond keeping accounts open. It is also entirely mechanical, which makes it exactly the right thing to automate.

What a custom build does: one internal data set, many output shapes. Customer specific export templates are configuration rather than code, so the compliance team adds a new customer format themselves. Submissions and responses are logged against the customer and the product so the next request is answered from history rather than rebuilt. The measurable win in our delivery experience is that a customer disclosure request drops from days of assembly to a review of a generated pack.

What this costs and how long it takes

Across the 2,000 plus projects Digital Heroes has delivered, this category runs a first release of $60,000 to $140,000 in 12 to 16 weeks. That covers declaration intake with extraction and matching, the part level substance data model, ERP and PLM bill of material integration, and automated rollup with a computed basis for each product. The full platform, adding supplier campaign management, list change monitoring with re evaluation, SCIP and CMRT outputs, customer specific export templates and a supplier facing portal, runs $180,000 to $400,000 phased over 6 to 12 months.

What drives the number up:

  • The number of regulatory regimes you report against, since each carries its own threshold logic, exemption handling and output format.
  • Bill of material complexity, especially configurable products and heavy use of alternates, which makes resolution rules genuinely hard.
  • PLM integration, which varies enormously between Teamcenter, Windchill, Arena and a home grown structure database.
  • Historical backfill, meaning how many years of existing declarations you want extracted and matched rather than starting clean from today.
  • Multi division rollout where each division numbers parts differently and insists it is correct.

What keeps it down: start with one product line, one regime, and your top 500 purchased parts by spend. That usually covers the majority of your customer requests and proves the extraction accuracy before you scale it.

Build versus buy, and when the subscription is the right call

Buy if you have a few hundred purchased parts, one product line and one regulated market. Assent and iPoint will chase your suppliers better than you will, and the subscription will be cheaper than running your own system. Buy the campaign capability even if you build, in many cases: supplier chasing is a relationship business and the platforms have the clout of asking on behalf of many customers at once.

Build when two or more of these are true. You carry several thousand purchased parts across product lines with different structures. Your rollup depends on one person's workbook and that person has no realistic backup. You have configurable products where the compliance answer depends on the configuration ordered. Your customers each demand a different output format and your team rebuilds packs by hand every quarter. You have been asked, or expect to be asked, for full material disclosure rather than a simple compliance statement, which is a far harder data problem.

The honest hybrid is common and we recommend it often: subscribe for supplier campaigns and list monitoring, build the part matching, rollup, statement versioning and customer output layer that the subscription cannot fit around your product structures. That combination usually costs less than forcing either approach to do the whole job.

How to choose a developer for product stewardship software

Ask them to whiteboard the data model. A developer who has done this draws part, manufacturer part, supplier declaration with scope and date, substance with a threshold basis, bill of material revision, and issued statement as a versioned object. If they draw parts and substances in a two table diagram, they have not met an alternate part or a phantom assembly yet.

Ask specifically how they handle homogeneous material level for RoHS versus part weight percentages for other regimes. If the answer treats every threshold the same way, your outputs will be wrong in a manner that is hard to detect and embarrassing to correct.

Ask what extraction accuracy they will commit to and how it is measured. The right answer includes a confirmation queue, a provenance link from every extracted value to the source page, and a rate that improves with corrections. Any claim of fully automatic extraction with no human review is a claim you should not accept on data you sign for.

Ask about ERP and PLM integration by name and version. A Teamcenter structure query is not a Windchill one, and pulling the as bought supplier part against a bill of material line is a different question from pulling the engineering structure. Vague integration claims here become months.

Ask who owns the code and settle it before kickoff. You should own the repository, the infrastructure and the right to move the work elsewhere. At Digital Heroes the code is yours from the first commit. On a system that underwrites statements you sign, holding your own compliance evidence is not negotiable.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey reports that autonomous supply-chain planning can raise revenue up to 4%, reduce inventory up to 20%, and cut supply-chain costs up to 10% while maintaining service levels (the wider 20-30% inventory-reduction figure comes from McKinsey's separate distribution-operations research, not this page). Source: McKinsey & Company (2020) →
  2. Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
  3. A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
  4. Workers can expect 39% of their existing skill sets to be transformed or become outdated over 2025-2030; 77% of employers plan to upskill their workforce, and 63% identify skill gaps as the biggest barrier to business transformation. Source: World Economic Forum (2025) →
Parth Srivastav · General Manager · Delhi

As General Manager, Parth connects commercial decisions to what the delivery teams can realistically build. Scope, pricing structure, team shape and account health all cross his desk. His writing is useful for anyone trying to work out what a software project should cost and why.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom REACH and RoHS compliance software cost for a manufacturer?
A first release covering declaration intake with extraction, part level substance data, bill of material integration and automated rollup typically runs $60,000 to $140,000 and ships in 12 to 16 weeks, based on Digital Heroes delivery experience. A full platform adding supplier campaigns, list change monitoring, SCIP and conflict minerals outputs and customer specific exports runs $180,000 to $400,000 over 6 to 12 months. Cost rises with the number of regulatory regimes and with configurable product structures. Historical backfill of old declarations is a separate line item worth scoping deliberately.
Is Assent or iPoint enough, or do we need to build our own system?
For a few hundred purchased parts in one regulated market, a subscription is the better economics and they chase suppliers more effectively than an internal team can. Where they struggle is your side of the fence: matching supplier documents to your part numbering and approved vendor list, respecting alternates and phantom assemblies, and computing a statement against your own product structures. Many manufacturers end up with a hybrid, subscribing for campaigns and list monitoring while building the matching, rollup and customer output layer.
How do you roll substance data up a bill of materials correctly?
By encoding your own structure rules rather than assuming arithmetic. Phantom assemblies must be collapsed, alternates resolved to what was actually purchased, and process chemicals such as plating, flux and adhesives attached at operation level even though they rarely appear on the bill of material. Threshold logic also differs by regime, since RoHS restrictions apply at homogeneous material level while other obligations use part or article weight. The output should show which parts contributed, which are evidenced and which are assumed.
What happens when the REACH candidate list is updated?
The candidate list of substances of very high concern is updated periodically, usually twice a year, and an update can make a long standing part reportable without anything changing in your product. A good system re evaluates every affected product automatically and produces two queues: parts needing a fresh supplier declaration, and customers holding a statement that is now stale. Reaching those customers before their auditor does is the difference between a routine update and a supplier quality escalation.
Can AI read supplier declarations reliably enough to trust?
It can do the reading, not the signing. Document extraction handles the hundred different PDF layouts well and pulls substance tables, declaration scope, signatory and date into your schema, and part matching resolves supplier part strings against your approved vendor list. Both should feed a human confirmation queue with a provenance link from every value back to the source page. Any vendor promising fully automatic extraction with no review on data you legally attest to is selling you a risk, not a saving.
How do we answer customer disclosure requests that all use different templates?
Hold one internal data set and treat every customer format as an output template that your compliance team can configure without a developer. Log each submission against the customer and the product so the next request starts from history instead of a blank workbook. This is mechanical work that creates no value beyond keeping accounts open, which makes it the highest return automation in the whole category. In our delivery experience a disclosure pack moves from days of assembly to a review of a generated document.
Does this need to integrate with our PLM as well as our ERP?
Usually yes, because they answer different questions. PLM holds the engineering structure and revision history, ERP holds what was actually purchased against each line, and a compliance statement needs both. Integration effort varies a lot between Teamcenter, Windchill, Arena and a home grown structure database, so ask any developer to name the system and version they have worked with rather than accept a general claim. If only one connection is affordable at first, start with the source that determines what is physically in the box.
How long does a substance compliance build take to become useful?
A focused first release is useful in 12 to 16 weeks if it is scoped to one product line, one regime and the top few hundred purchased parts by spend. That covers most incoming customer requests and proves extraction and matching accuracy at a manageable scale. Widening to more regimes and divisions afterwards is mostly configuration and data work rather than new engineering. Backfilling years of historical declarations should be planned as its own phase with its own budget.
What if our suppliers simply will not respond to declaration requests?
That is a commercial problem before it is a software one, and no system solves it alone. What software does is make non response visible and expensive to ignore: response rate by supplier, parts at risk by revenue exposure, and escalation queues tied to purchasing reviews. Subscription platforms have real clout here because they ask on behalf of many customers at once, which is a legitimate reason to keep one alongside a custom build. For critical parts with no declaration, the honest option is qualification of an alternate.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
When is SAP actually a better choice than building custom supply chain software?
Choose SAP when you need a full ERP, operate in a heavily audited industry that expects standard systems, or run global operations where localization, tax, and compliance content matter more than workflow fit. SAP's strength is breadth: finance, manufacturing, and supply chain in one validated suite. Custom wins when your edge lives in a specific workflow, like how you allocate inventory or route orders, that SAP would force you to bend to its standard process. Many Digital Heroes clients keep SAP as the system of record and build custom operational tools around it.
What tech stack is best for custom supply chain software?
Boring and mainstream wins: a typed backend such as Node with TypeScript, Python, or C#, PostgreSQL for transactional inventory data, a React web frontend, and hosting on AWS, Azure, or GCP. Real-time needs like scanner feeds or live shipment tracking add a message queue such as Redis or RabbitMQ. Be wary of any agency pitching an exotic stack; in Digital Heroes handover work, systems built on niche frameworks are consistently the hardest and most expensive for a new team to take over.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
What happens to my software if the agency shuts down or we stop working together?
Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.
Will custom software scale as we add warehouses, SKUs, and order volume?
Yes, if multi-location support and your target volumes are stated requirements at design time, because a schema built for one warehouse is expensive to retrofit for ten. A well-built system on PostgreSQL comfortably handles millions of SKUs and tens of thousands of orders per day on modest cloud hardware, so scaling cost shows up in hosting bills rather than rewrites. Give your agency the 3-year growth picture upfront even if phase one covers a single site.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
Should we start with an MVP or build the full supply chain platform at once?
Start with an MVP that fixes your single most expensive workflow, prove it in daily operations, then expand module by module. That gets working software onto the warehouse floor in about 12 weeks instead of debating a year-long spec, and real usage always reorders the roadmap; features that felt critical in planning routinely get cut after go-live. Digital Heroes typically scopes phase one at 30 to 40 percent of the total vision and lets measured results justify each next phase.
Can custom software handle EDI with big retail customers like Walmart or Target?
Yes, and this is one of the most common reasons distributors go custom, because retailer scorecards penalize late or malformed documents. The typical build covers EDI 850 purchase orders in, 855 acknowledgments, 856 advance ship notices, and 810 invoices out, usually through a network like SPS Commerce or TrueCommerce rather than raw AS2. In Digital Heroes builds, onboarding your first major retailer adds 4 to 8 weeks and $10,000 to $25,000, with each additional trading partner far cheaper once the pipeline exists.
We are a growing distributor. Should we pick SAP Business One or go custom?
If you need full accounting, purchasing, and inventory in one system today, SAP Business One is the faster path; if your pain is operational workflows the ERP handles badly, custom is usually the better spend. Business One gives you a proven ledger and stock control, but changing its workflows means paying certified consultants, and the customization quotes Digital Heroes clients share commonly run $150 to $250 per hour for changes you never own. A pattern Digital Heroes builds often is Business One or QuickBooks as the financial core with a custom order, warehouse, or logistics layer on top.
Who can build a custom supply chain software system?

Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other supply chain software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?